Security1 distinct publisher3 min readPublished
A compiled timeline of identity-verification failures since 2011 puts nearly half the incidents in the category where what leaked was the face or the document itself.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The rate is the part the report leaves on the table. Thirty-seven of the 88 incidents fall inside the 32 months from January 2024 to August 2026 [5]. Treat the timeline as starting in January 2011 and the other 51 spread across roughly 156 months, which is about one incident a quarter in the older period against better than one a month in the recent one, a rate around three and a half times higher [19]. Some of that gap is an artefact of counting: a 2013 exposure is harder to find than a 2025 one. The rest is supply. Mandates create databases, and databases are what leave.
The concentration is the more useful detail for anyone buying this as a service. AU10TIX, which verifies identity for TikTok, Uber and X, left admin credentials exposed for more than a year [9]. Sumsub disclosed a support-system intrusion that ran undetected for 18 months [10]. Persona, which handles age verification for Discord and Roblox, exposed its own frontend configuration [11]. The report's claim is that every major vendor of this era appears somewhere in the timeline, naming AU10TIX, IDMerit, Sumsub, Persona and inVOID [12]. Outsourcing an age gate does not take the ID off your risk register. It moves the document into a company whose client list is the reason to attack it, and whose incidents you will hear about second.
Discord's case shows where the harm lands. The roughly 70,000 government IDs exposed through a third-party support provider belonged to users who had challenged an age-verification decision, meaning people who were trying to correct the system's judgement about them, and Discord carried on expanding age checks afterwards [8]. Tea, built as a women-only safety platform, lost verification selfies out of an open storage bucket, and the images later showed up on 4chan [7].
Government registries are in the same list at larger scale. Argentina's national identity system leaked 45 million records including ID scans and selfies [13], and France's ANTS, the agency that issues French identity documents, confirmed 11.7 million people affected in a 2026 breach [14]. Those two alone account for about 56.7 million [21], with India's Aadhaar, Thailand's visitor database, the Philippines' voter rolls and Brazil's tax registry also on the timeline [15].
Two cautions on the headline number. The compiler is a VPN company, Mysterium, which is worth holding in mind while reading its framing even though the incidents are individually checkable [1]. And the 4.54 billion attributed to attacker and seller claims is more than twice the verified figure [20], so the number to argue about is 2.15 billion [2]. The number to budget against is 41: the incidents where ID scans, verification selfies, fingerprints and biometric templates were part of what leaked, none of which can be reissued [4]. SecurityAffairs' reading is that leaning on a reputable third-party provider is not sufficient protection for firms weighing build against outsource [17], and the report's own conclusion is that this is one failure mode repeated across fifteen years and every type of organisation that decided to collect this category of data [16].
Ranked by verification strength, evidence, and original report placement.
The report states that every major identity-verification vendor of the current era, naming AU10TIX, IDMerit, Sumsub, Persona and inVOID, has appeared in its timeline.
The report concludes that the timeline shows one failure mode repeated across 88 incidents, fifteen years, and every type of organisation that has decided to collect this category of data.
A report from Mysterium VPN compiles 88 documented incidents since 2011 in which data collected specifically to verify someone's identity or age was breached, exposed, or sold.
The confirmed and researcher-verified total across the 88 incidents is 2.15 billion records.
Attacker and seller claims add a further 4.54 billion records on top of the verified total.
In 41 of the 88 incidents, what leaked included the source documents themselves: ID scans, verification selfies, fingerprints and full biometric templates, none of which can be changed like a password.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-outlet relay of one vendor-authored dataset
Every factual element traces to one article summarising one report, with no link to the underlying dataset, no methodology for incident selection or de-duplication, no per-incident dates or counts, and no vendor responses. The article does usefully separate researcher-verified records from attacker and seller claims, and the individual named incidents are specific and checkable in principle, which keeps this above the floor. But 4.54 billion of the 6.69 billion headline records are explicitly unverified, and the derived rate and percentage figures rest entirely on the report's aggregates.
Verification layer is already in production at major-platform scale
Adoption of the technology under scrutiny is concretely disclosed rather than projected: AU10TIX verifies identity for TikTok, Uber and X, Persona runs age verification for Discord and Roblox, and Discord kept expanding age checks even after roughly 70,000 appeal IDs leaked through a support provider. National systems in Argentina, France, India, Thailand, the Philippines and Brazil place the same pattern at country scale. The score is held below high because the article gives no volumes, contract values or coverage percentages for these deployments.
Headline volume leans on unverified claims; core counts are solid
Mildly overstated. The framing amplifies a 6.69 billion-record impression when only 2.15 billion is researcher-verified, and the sweeping conclusions — 'one failure mode' across fifteen years, and every major vendor implicated — are the report author's interpretation with no root-cause breakdown or vendor rebuttal offered. Offsetting this, the article is explicit about which figures are unverified, and the anchor statistic that matters most (41 of 88 incidents leaking non-resettable documents and biometrics) is stated plainly and is directly consequential, so the gap is moderate rather than large.
Report author is a privacy-product vendor; conclusion favours its market
The dataset is authored by Mysterium VPN, a privacy-tooling company whose commercial narrative is served by the conclusion that mandatory ID and age collection is inherently unsafe, and the article does not disclose that alignment. The named verification vendors and the platforms that use them have the opposite incentive and are given no voice. SecurityAffairs itself has a topical-traffic incentive in breach-count aggregations. This is a clear, structural incentive load, though not a paid-placement or undisclosed-relationship situation on the evidence supplied.
Directionally credible, quantitatively soft
Confidence is moderate-low. The direction of the story — that identity and age verification data is repeatedly exposed, increasingly so as mandates spread, and that verification vendors are themselves failure points — is supported by multiple specific, named incidents and is consistent with the disclosed deployment footprint. Precision is the weak point: one publisher, one vendor-authored dataset with no published methodology, and a headline record volume dominated by unverified attacker claims. Treat the pattern as usable and the numbers as provisional.
product
Roblox counts 28 clicks, 21 of them purchases, as an eight-year-old's waiver1 distinct publisher
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
product
France's under-15 ban failed on the age check, not the age limit1 distinct publisher
build
Search Console starts reporting on posts you do not host, if you can verify them1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026